Aug 24: StackGres 9.9, GitLab RCE, Zimbra KEV
StackGres CVSS 9.9 tenant escalation confirmed. GitLab patches RCE in package registry. CISA three-day deadline on Zimbra CVE-2026-73570. Iran sanctions, UK ICS breach.
- CVE-2026-78155 (StackGres, CVSS 9.9): database tenant privilege escalation to full cluster admin. Exploitable by authenticated database users. No CVE patch window — upgrade StackGres immediately.
- CVE-2026-10053 (GitLab, CVSS 8.5): remote code execution in the package registry via malicious packages. GitLab.com patched. Self-managed instances require manual upgrade.
- CVE-2026-73570 (Zimbra): CISA issued a three-day patch deadline for federal agencies. Active exploitation in the wild confirmed. OS command injection enabling full account takeover.
- US Treasury sanctioned Iranian nationals for cyberattacks on critical infrastructure. UK attributed a cyber intrusion at a small power plant to Iranian-linked actors.
- CVE-2026-19200 (Velociraptor): artifact overwrite flaw patched — no active exploitation confirmed, but impact is evidence integrity on active hunts.
- miniOrange SAML SSO plugin: two critical authentication bypass flaws under active attack on WordPress sites. CVE IDs pending. Update the plugin immediately.
Seven items on the board today. Three require immediate action.
StackGres CVE-2026-78155 — CVSS 9.9, tenant escalation to cluster admin
Patch now. CVE-2026-78155 in StackGres allows an authenticated database tenant to escalate privileges to full Kubernetes cluster administrator. CVSS: 9.9. Attack path: a user with any database credentials can escape tenant isolation and take full control of the cluster running StackGres.
Confidence breakdown:
- Confirmed: CVE assigned, CVSS 9.9 from vendor advisory via GitLab issue tracker.
- Confirmed: Privilege escalation from tenant to cluster admin is the stated impact.
- Unknown: Whether active exploitation has been observed in the wild. No KEV listing as of this writing.
If you run StackGres in a multi-tenant environment, treat this as a live breach risk until patched. Any user with database access is a potential cluster-level threat actor. Upgrade immediately. Full coverage: StackGres CVSS 9.9 Bug Escalates DB Tenant to Admin.
GitLab CVE-2026-10053 — RCE via package registry
Patched. GitLab addressed CVE-2026-10053, a remote code execution vulnerability in the package registry component, with CVSS 8.5. Attack vector: malicious packages uploaded to the registry can trigger code execution on the GitLab server. Exploitation requires the ability to upload packages.
Confidence:
- Confirmed: CVE, CVSS, and patch confirmed via GitLab advisory.
- Unconfirmed: Active exploitation in the wild. Treat as high priority given the attack surface.
GitLab.com is patched. Self-managed GitLab instances require an upgrade to the patched release. If your instance has open package registry uploads, exposure is elevated. Full coverage: GitLab Patches RCE in Package Registry (CVE-2026-10053).
Zimbra CVE-2026-73570 — CISA three-day deadline, active exploitation
Active. CISA has issued a three-day patch deadline for federal agencies on CVE-2026-73570, the Zimbra Collaboration Suite OS command injection vulnerability. Active exploitation in the wild was confirmed before the KEV listing on August 21 — that window has not closed. Dark Reading reports the deadline is in effect as of today.
Confidence:
- Confirmed: CVE, active exploitation, KEV listing Aug 21, CISA deadline reported.
- Confirmed: Patch available — Zimbra 10.1.20 released July 2026.
If you are running a patched Zimbra version: nothing new required. If you are not: this is not a drill. CVE was disclosed with active exploitation and is now under a federal emergency timeline. Full coverage at the week’s prior desk briefing and: Zimbra SNMP RCE Now Exploited in the Wild.
US sanctions Iranian hackers — UK power plant ICS breach
Geopolitical context. The US Treasury sanctioned multiple Iranian nationals for cyberattacks against critical infrastructure. Concurrent with the announcement, UK authorities disclosed a cyber intrusion at a small British power plant, attributed to Iranian-linked actors, per The Record.
Confidence:
- Confirmed: US Treasury sanction announcement confirmed; Iranian individuals named.
- Confirmed: UK power plant intrusion attributed to Iranian-linked actors per UK official statements.
- Unknown: Technical details of the UK intrusion — attack vector, systems affected, data accessed.
The combination of sanctions and a concurrent attributed ICS breach raises the baseline threat level for energy-sector OT environments. If you operate ICS in critical infrastructure, this is context for your current defensive posture — not a specific CVE action item. Monitor US-CERT and CISA for any follow-on advisories.
Velociraptor CVE-2026-19200 — artifact overwrite, patched
Patched, no active exploitation confirmed. CVE-2026-19200 in Velociraptor allows analysts with write access to overwrite forensic artifacts on hunts in progress. Impact: evidence integrity, not remote code execution. An attacker or rogue insider with the appropriate permissions could alter the forensic record being collected.
Confidence:
- Confirmed: CVE, patch confirmed.
- Confirmed: No active exploitation in the wild at time of reporting.
If your IR team uses Velociraptor for live hunts, update and audit artifact integrity controls. Full coverage: Velociraptor Flaw Lets Analysts Overwrite Artifacts.
Also today
- miniOrange SAML SSO — active WordPress attacks (no CVE IDs confirmed yet): Two critical authentication bypass flaws in the miniOrange SAML 2.0 Single Sign On plugin for WordPress are under active exploitation. Attackers are forging SAML responses to authenticate as arbitrary users, including administrators. CVE IDs pending. If miniOrange SAML SSO is installed, disable it or update immediately — do not wait for CVE assignment. Source: BleepingComputer.
- Calix GS7 XGS — unpatched NAT bypass: An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by US broadband providers lets an unauthenticated remote attacker create port-forwarding rules that expose internal devices. No patch from Calix as of reporting. Confidence: BleepingComputer report confirmed; patch availability: none. ISPs deploying this hardware should assess exposure. Source: BleepingComputer.
- ReliaQuest / ShinyHunters: ReliaQuest confirmed that ShinyHunters breached a single employee dashboard via phishing. Company states impact was limited to that dashboard and no client data was accessed. Confidence: Company-confirmed via SecurityWeek. ShinyHunters has a documented pattern of overstating breach scope — treat the company’s impact assessment as official, but watch for conflicting claims from the threat actor.
- TikTok $400M COPPA settlement: US DOJ announced a $400 million settlement with TikTok and ByteDance for Children’s Online Privacy Protection Act violations. No security-operation action item for most readers; relevant context for privacy and compliance teams.
What to watch
- StackGres CVE-2026-78155 KEV listing. CVSS 9.9 privilege escalation on database infrastructure is a high-profile KEV candidate. Watch the CISA catalog.
- GitLab CVE-2026-10053 exploitation. Package registry RCE on self-managed instances is a plausible target for threat actors who scan for vulnerable GitLab versions. Exploitation confirmation expected within days if it occurs.
- Zimbra CVE-2026-73570 FCEB deadline compliance. Three-day federal deadline means we’ll have visibility into whether agencies patched on time. Watch for post-deadline CISA reporting.
- miniOrange SAML CVE assignment. Active exploitation with no CVE ID means patch management tooling isn’t tracking it yet. CVE assignment from WPScan or MITRE will be the signal for automated alerting to catch up.
- Iran ICS threat posture. Treasury sanctions + confirmed power plant intrusion is a pre-action pattern. Watch for additional CISA or NCSC advisories specific to the energy sector.
— airgap
- GitLab security advisory — CVE-2026-10053
- StackGres advisory — CVE-2026-78155
- Dark Reading — Exploited Zimbra Flaw Highlights Shrinking Window to Patch
- The Record — US sanctions Iranian cyber actors as UK discloses power plant attack
- BleepingComputer — Hackers target WordPress sites in miniOrange auth bypass attacks
- BleepingComputer — Unpatched Calix flaw lets hackers bypass NAT to expose internal devices
- SecurityWeek — ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited